<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[startupciso]]></title><description><![CDATA[Smart security for companies who would rather be shipping great stuff. ]]></description><link>https://startupciso.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!V94F!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fstartupciso.substack.com%2Fimg%2Fsubstack.png</url><title>startupciso</title><link>https://startupciso.substack.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 21 Jun 2026 15:14:25 GMT</lastBuildDate><atom:link href="https://startupciso.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[startupciso]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[startupciso@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[startupciso@substack.com]]></itunes:email><itunes:name><![CDATA[LaPalice]]></itunes:name></itunes:owner><itunes:author><![CDATA[LaPalice]]></itunes:author><googleplay:owner><![CDATA[startupciso@substack.com]]></googleplay:owner><googleplay:email><![CDATA[startupciso@substack.com]]></googleplay:email><googleplay:author><![CDATA[LaPalice]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Startups and security : when does it become relevant ?]]></title><description><![CDATA[When I tell my friends I make most of my money as a cybersecurity consultant with startups, their reactions range from nicely surprised to lowkey angry.]]></description><link>https://startupciso.substack.com/p/startups-and-security-when-does-it</link><guid isPermaLink="false">https://startupciso.substack.com/p/startups-and-security-when-does-it</guid><dc:creator><![CDATA[LaPalice]]></dc:creator><pubDate>Mon, 08 Feb 2021 11:05:47 GMT</pubDate><content:encoded><![CDATA[<p>When I tell my friends I make most of my money as a cybersecurity consultant with startups, their reactions range from nicely surprised to lowkey angry. Some of them are entrepreneurs, and they would never imagine putting a dime in security at their current stage of development. They wonder where my customers find the money to afford security consulting &#8211; let alone costly security solutions.</p><p>When I ask them to elaborate on their own businesses, and that I point out some risks, I&#8217;m quite often told that they are aware of the risk, but they clearly consider that mitigating these risks is the last stage of development. You start with building a great product, you spend endless amount of time iterating to make it better, and then one day, you will probably have a security epiphany and you will start &#8220;doing cybersecurity&#8221;.&nbsp;</p><p>I think they&#8217;re wrong. From my experience, you start with building a great product, you iterate to make it better, you look for customers along the way, and then you build this feature you promised you would never build because client X that makes most of your revenue wants it yesterday, and then you deal with user feedback and demands and whatnot, and&#8230; your security epiphany is often losing a contract because big account Y sends you a security questionnaire and you have none of the answers. And this is the best case scenario &#8211; the worst case being an actual data breach or cyberattack.</p><p>If you are lucky, your CTO has some clues about security and will implement stuff the right way, but here is the thing: all companies consider themselves too early in the process to start thinking about the security. What I hear most is &#8220;we are not doing it at the moment&nbsp;; but we will when we grow&nbsp;!&#8221;.</p><p>And I get that. This is a very common paradox that goes way beyond security. You know that you should spend 10 minutes a day tidying your living-room but guess who is going to panic-clean on Sunday morning because your in-laws will arrive home in one hour&nbsp;? Security is the same. It&#8217;s always easier to do thing right from the beginning, but it&#8217;s not rewarding to do so. And this goes especially when running an early stage startup.&nbsp;&nbsp;Security is process, while you are yearning creativity and seamlessness&nbsp;; it&#8217;s cost, when you aim at becoming profitable&nbsp;; it takes a &#8220;what could go wrong&#8221; mindset when you so desperately need optimism to keep going.</p><h2>20.000 miles under the sea</h2><p>But you know you need it, of course. I&#8217;m not going to write the usual paragraph about the cost of a data breach, or&nbsp;&nbsp;GDPR fines, because I don&#8217;t think it&#8217;s how you should think about security. The reason you need security is for pure, sheer business reasons.</p><p>I like to think of security as your scubadiving outfit. Building a startup is a bit like exploring the bottom of the ocean. There is a ton of unveiled potential, exciting treasures that may be waiting for you, and the deeper you go, the more promising it gets.</p><p>But you cannot just dive 20 000 miles under the se ajust because you want to get there. If you hold your breath, you might be able to dive some meters. With a tuba, you still cannot go very deep, but you can stay longer and explore. Get a scubadiving outfit and some hours of training, and suddenly you are 50-100 meters under the surface, and free to explore for way longer. And one day, if you build the right submarine, you might end up finding this treasure no one has found before.&nbsp;</p><p>The same applies to security. Are you planning on doing disruptive AI-based behavioral analysis on healthcare data? With the right security measures, no one is stopping you, and the barrier to entrance will be high enough to get you ahead of competition for a while. It&#8217;s the same if you want to get that big customer: their security demands will be higher than you regular SMB, so will the price they are willing to pay.</p><p>Of course, you need to get the right outfit at the right moment. You&#8217;re not going to buy a submarine to explore the lake 20 kms from home. And you&#8217;re not going to run pentests on the prototype that is supposed to get you some pre-seed money. But not buying the tuba because you plan to get the whole submarine at once when your company grow is going to take a lot more time and money than you expect&nbsp;; and you will be missing opportunities while catching up.</p><p>Let me get give you the dumbest example. One of the basics of security is that you cannot protect what you don&#8217;t know about. And, trust me, it&#8217;s harder than it sounds (I recently spent more than 6 weeks at a big customer doing back and forth about specific parts of their Active Directory because nobody was able to know what machines were located in there, and who was in charge of making sure they were secure).</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/hacks4pancakes/status/1352427660480307202&quot;,&quot;full_text&quot;:&quot;Weeks into formal and informal response to Solarwinds Orion IR, and the biggest hurdle to IR I am still seeking is that organizations do not know if they have *found* all of their Solarwinds Orion installations, and what versions they are actually running.&quot;,&quot;username&quot;:&quot;hacks4pancakes&quot;,&quot;name&quot;:&quot;Lesley Carhart&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Fri Jan 22 01:27:35 +0000 2021&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:120,&quot;like_count&quot;:789,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/hacks4pancakes/status/1352429094877724672&quot;,&quot;full_text&quot;:&quot;I am an inappropriately expensive asset management and discovery tool. Even when paid off the record in food. Fix your basic security hygiene before the next big supply chain attack.&quot;,&quot;username&quot;:&quot;hacks4pancakes&quot;,&quot;name&quot;:&quot;Lesley Carhart&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Fri Jan 22 01:33:17 +0000 2021&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:52,&quot;like_count&quot;:461,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>But you are a startup&nbsp;! You probably have X and X, your codebase is still quite knew and, sure enough your CTO STILL knows all parts of the project. If you start with a robust asset management process, you may not end up trying to remember who mentioned they have a PoC running with Solaris one year from now, or if you still run that outdated version of Drupal for that one customer who is not willing to upgrade.</p><h2>The right diving outfit</h2><p>This is what this series of blog is about: trying to assess the right diving outfit for the right project, and building a business-centric approach of cybersecurity for the startup stage, that follows the main stages of building a startup. What should you do when crafting your business plan? When developing your prototype with freelance developers? When hiring your core team? When getting your first customers? Our common goal should be to maximize what you get from security, while minimizing costs and efforts. I hope you&#8217;ll find this worth it.</p>]]></content:encoded></item><item><title><![CDATA[Smart security for companies who would rather be shipping. ]]></title><description><![CDATA[Welcome to startupciso by me, startupciso.]]></description><link>https://startupciso.substack.com/p/coming-soon</link><guid isPermaLink="false">https://startupciso.substack.com/p/coming-soon</guid><dc:creator><![CDATA[LaPalice]]></dc:creator><pubDate>Mon, 18 Jan 2021 20:18:50 GMT</pubDate><content:encoded><![CDATA[<p>Welcome to startupciso by me, startupciso. </p><p>Sign up now so you don&#8217;t miss the first issue.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://startupciso.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://startupciso.substack.com/subscribe?"><span>Subscribe now</span></a></p><p>In the meantime, <a href="https://startupciso.substack.com/p/coming-soon?utm_source=substack&utm_medium=email&utm_content=share&action=share">tell your friends</a>!</p>]]></content:encoded></item></channel></rss>